pingcap records
7 published records for vendor pingcap.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-476 NULL Pointer Dereference2
- CWE-134 Use of Externally-Controlled Format String1
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-3023No exploit | Use of Externally-Controlled Format String in pingcap/tidbpingcap · tidb · CWE-134 | Critical9.8 | — | 0.6% | Nov 4, 2022 |
39Monitor | CVE-2024-41433No exploit | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList.pingcap · tidb · CWE-120 | Critical9.8 | — | 0.6% | Sep 3, 2024 |
31Monitor | CVE-2022-31011No exploit | TiDB authentication bypass vulnerabilitypingcap · tidb · CWE-287 | High7.8 | — | 0.3% | May 31, 2022 |
30Monitor | CVE-2022-34969No exploit | PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.pingcap · tidb · CWE-476 | High7.5 | — | 0.9% | Aug 2, 2022 |
30Monitor | CVE-2024-35618No exploit | PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.pingcap · tidb · CWE-476 | High7.5 | — | 0.4% | May 24, 2024 |
26Monitor | CVE-2024-33809No exploit | PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service atpingcap · tidb · CWE-120 | Medium6.5 | — | 0.4% | May 24, 2024 |
17Monitor | CVE-2024-41434No exploit | PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal.pingcap · tidb · CWE-400 | Medium4.3 | — | 0.4% | Sep 3, 2024 |
- CVE-2022-302339Monitor
Use of Externally-Controlled Format String in pingcap/tidb
CriticalCVSS 9.8No exploitEPSS 1%pingcap · tidbNov 4, 2022
- CVE-2024-4143339Monitor
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component expression.ExplainExpressionList.
CriticalCVSS 9.8No exploitEPSS 1%pingcap · tidbSep 3, 2024
- CVE-2022-3101131Monitor
TiDB authentication bypass vulnerability
HighCVSS 7.8No exploitEPSS 0%pingcap · tidbMay 31, 2022
- CVE-2022-3496930Monitor
PingCAP TiDB v6.1.0 was discovered to contain a NULL pointer dereference.
HighCVSS 7.5No exploitEPSS 1%pingcap · tidbAug 2, 2022
- CVE-2024-3561830Monitor
PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.
HighCVSS 7.5No exploitEPSS 0%pingcap · tidbMay 24, 2024
- CVE-2024-3380926Monitor
PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service at
MediumCVSS 6.5No exploitEPSS 0%pingcap · tidbMay 24, 2024
- CVE-2024-4143417Monitor
PingCAP TiDB v8.1.0 was discovered to contain a buffer overflow via the component (*Column).GetDecimal.
MediumCVSS 4.3No exploitEPSS 0%pingcap · tidbSep 3, 2024